feat: wire capability tokens and the audit trail through CLI, REPL and web

The risk model, grants and hash-chained trail existed as modules nothing
called. Now every engagement runs under them.

Capability
- `neurosploit capability issue|verify` mints and inspects grants.
- `--capability-token` (global, so the REPL takes it too), `--in-scope`,
  `--environment`, `--policy` on `run`; verification happens at the command
  line, so an invalid grant fails with a readable message instead of halfway
  through an engagement.
- The pipeline verifies before anything else and REFUSES to run on a token that
  does not verify — proceeding would mean acting on an authorization nobody can
  prove was issued. `effective_scope` then applies the grant as a ceiling.
- Web: an Authorization tab carrying the token, extra hosts, environment and
  policy profile. The browser decodes the claims for display and says plainly
  that it is not verifying them — a "valid" badge from a party without the key
  would be the UI vouching for something it cannot check.

A hole the smoke test found: `/inscope evil.test` inside a session under a
grant WIDENED the scope past it — the one thing a capability token exists to
prevent. The run itself would still have been constrained (the pipeline
re-applies the grant), but `/policy` reported a boundary that was not real, and
a tool that misreports its own limits is worse than one with none. Scope
mutations now re-apply the ceiling and name what it refused. Session
authorization also arrives from argv rather than a `/`-command, because a
session that can widen its own grant is not constrained by one.

Audit
- One hash-chained record per action in `<run>/audit.jsonl`, in the specified
  shape, covering engagement start/end, validator rejections, findings that
  reach the report (with the hash of the evidence behind them) and findings
  withheld for being out of scope.
- The run verifies its own chain at the end and says loudly if it is broken.
- `/audit [n]` tails the trail and verifies it; the web offers it as a download
  next to the report, so "show me what the tool did" is a link.

Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>
This commit is contained in:
CyberSecurityUP
2026-09-13 19:18:32 -03:00
co-authored by Claude Opus 5
parent 3456c32f4d
commit 481a4eb1b9
8 changed files with 607 additions and 13 deletions
+24 -3
View File
@@ -454,7 +454,7 @@ async function runDetail(id) {
readJsonSafe(path.join(dir, 'status.json'), {}),
readJsonSafe(path.join(dir, 'findings.json'), []),
]);
const assets = ['report.html', 'report.pdf', 'report.md', 'recon.md', 'exploitation.md']
const assets = ['report.html', 'report.pdf', 'report.md', 'recon.md', 'exploitation.md', 'audit.jsonl', 'graph.json']
.filter((f) => fs.existsSync(path.join(dir, f)));
const pocs = await fsp.readdir(path.join(dir, 'pocs')).catch(() => []);
return { id, name: engagementNames.get(id) || '', meta, status, findings, assets, pocs };
@@ -588,6 +588,12 @@ function buildArgs(body) {
if (body.focus) args.push('--focus', body.focus);
if (body.objective) args.push('--objective', body.objective);
if (body.outOfScope) args.push('--out-of-scope', body.outOfScope);
// Authorization: the signed grant caps the scope, the extra in-scope entries
// can only narrow within it, and the environment scales every risk score.
for (const entry of body.inScope || []) args.push('--in-scope', entry);
if (body.capability) args.push('--capability-token', body.capability);
if (body.environment) args.push('--environment', body.environment);
if (body.policyProfile) args.push('--policy', body.policyProfile);
for (const a of body.agents || []) args.push('--only', a);
args.push('--verbose');
return args;
@@ -635,6 +641,18 @@ async function startJob(body) {
/// engagement (`/target`/`/repo` → `/model` → toggles → `/only` → `/run`).
/// `/only` is what makes this equivalent to the CLI's `--only` — REPL had no
/// such command before this feature (added to app/src/repl.rs alongside it).
/// Flags that apply to every mode, including the REPL-backed one. The REPL
/// takes them as argv because a `/`-command for an authorization ceiling would
/// let the session widen its own grant mid-run.
function authArgs(body) {
const args = [];
for (const entry of body.inScope || []) args.push('--in-scope', entry);
if (body.capability) args.push('--capability-token', body.capability);
if (body.environment) args.push('--environment', body.environment);
if (body.policyProfile) args.push('--policy', body.policyProfile);
return args;
}
function buildReplScript(body) {
const lines = [];
if (body.mode === 'whitebox') lines.push(`/repo ${body.repo || body.target}`);
@@ -670,12 +688,15 @@ async function startJobViaRepl(body) {
const id = crypto.randomUUID();
const credsPath = await materializeCreds(body, id);
const script = buildReplScript({ ...body, creds: credsPath });
const job = new Job(id, BIN, [], body.repo || body.target || '', body.name || '');
const auth = authArgs(body);
const job = new Job(id, BIN, auth, body.repo || body.target || '', body.name || '');
job.pinnedAgents = body.agents || [];
job.repl = true;
jobs.set(id, job);
const child = spawn(BIN, [], { cwd: ROOT, env: { ...process.env, ...envOverrides() } });
// The REPL session inherits the engagement's authorization from argv, so the
// ceiling is set before the first command is scripted into it.
const child = spawn(BIN, auth, { cwd: ROOT, env: { ...process.env, ...envOverrides() } });
job.child = child;
let buf = '';
const onData = (chunk) => {